security: remove hardcoded credentials, untrack .env
- config/system_config.py: defaults are localhost with empty credentials; real hosts/secrets must come from env (.env or docker-compose) - main.py: help text lists env var names instead of real NATS host/user - doormile_test.py: reads infra config from env instead of literals - untrack .env, ignore .env/.env.*, add .env.example with keys only - pytest.ini: testpaths=tests so doormile_test.py isn't collected Credentials remain in git history and must be rotated. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_012AJLYcbTHCe45fyFnMfEin
This commit is contained in:
16
.env.example
Normal file
16
.env.example
Normal file
@@ -0,0 +1,16 @@
|
|||||||
|
GO_API_BASE_URL=
|
||||||
|
NATS_URL=
|
||||||
|
REDIS_HOST=
|
||||||
|
REDIS_PORT=
|
||||||
|
REDIS_PASSWORD=
|
||||||
|
INTERNAL_API_KEY=
|
||||||
|
DB_HOST=
|
||||||
|
DB_PORT=
|
||||||
|
DB_NAME=
|
||||||
|
DB_USER=
|
||||||
|
DB_PASSWORD=
|
||||||
|
NATS_USER=
|
||||||
|
NATS_PASSWORD=
|
||||||
|
ANTHROPIC_API_KEY=
|
||||||
|
LLM_MODEL=claude-opus-4-8
|
||||||
|
LOG_LEVEL=INFO
|
||||||
5
.gitignore
vendored
5
.gitignore
vendored
@@ -7,3 +7,8 @@ venv/
|
|||||||
|
|
||||||
.idea/
|
.idea/
|
||||||
.vscode/
|
.vscode/
|
||||||
|
|
||||||
|
# secrets
|
||||||
|
.env
|
||||||
|
.env.*
|
||||||
|
!.env.example
|
||||||
|
|||||||
@@ -1,27 +1,28 @@
|
|||||||
"""System configuration for LogiFlow AI."""
|
"""System configuration for LogiFlow AI."""
|
||||||
import os
|
import os
|
||||||
|
|
||||||
# Infrastructure Connections — values come from environment / .env file.
|
# Infrastructure Connections — values come from environment / .env file
|
||||||
# Hardcoded strings are last-resort defaults; set the matching env var in production.
|
# (see .env.example). Defaults point at localhost with no credentials so the
|
||||||
NATS_URL = os.getenv("NATS_URL", "nats://doormile:Package@321#@66.116.226.161:4223")
|
# system runs in local-fallback mode; real hosts and secrets are never in code.
|
||||||
NATS_HOST = os.getenv("NATS_HOST", "66.116.226.161")
|
NATS_URL = os.getenv("NATS_URL", "nats://localhost:4222")
|
||||||
NATS_PORT = int(os.getenv("NATS_PORT", "4223"))
|
NATS_HOST = os.getenv("NATS_HOST", "localhost")
|
||||||
NATS_USER = os.getenv("NATS_USER", "doormile")
|
NATS_PORT = int(os.getenv("NATS_PORT", "4222"))
|
||||||
NATS_PASSWORD = os.getenv("NATS_PASSWORD", "Package@321#")
|
NATS_USER = os.getenv("NATS_USER", "")
|
||||||
|
NATS_PASSWORD = os.getenv("NATS_PASSWORD", "")
|
||||||
|
|
||||||
REDIS_HOST = os.getenv("REDIS_HOST", "66.116.226.255")
|
REDIS_HOST = os.getenv("REDIS_HOST", "localhost")
|
||||||
REDIS_PORT = int(os.getenv("REDIS_PORT", "6380"))
|
REDIS_PORT = int(os.getenv("REDIS_PORT", "6379"))
|
||||||
REDIS_PASSWORD = os.getenv("REDIS_PASSWORD", "Package@321#")
|
REDIS_PASSWORD = os.getenv("REDIS_PASSWORD", "")
|
||||||
|
|
||||||
# Postgres — individual params to avoid @ in password breaking DSN parsing
|
# Postgres — individual params to avoid @ in password breaking DSN parsing
|
||||||
DB_HOST = os.getenv("DB_HOST", "31.97.228.132")
|
DB_HOST = os.getenv("DB_HOST", "localhost")
|
||||||
DB_PORT = int(os.getenv("DB_PORT", "5433"))
|
DB_PORT = int(os.getenv("DB_PORT", "5432"))
|
||||||
DB_NAME = os.getenv("DB_NAME", "logistics")
|
DB_NAME = os.getenv("DB_NAME", "logistics")
|
||||||
DB_USER = os.getenv("DB_USER", "admin")
|
DB_USER = os.getenv("DB_USER", "postgres")
|
||||||
DB_PASSWORD = os.getenv("DB_PASSWORD", "Package@321#")
|
DB_PASSWORD = os.getenv("DB_PASSWORD", "")
|
||||||
|
|
||||||
GO_API_BASE_URL = os.getenv("GO_API_BASE_URL", "http://localhost:8080")
|
GO_API_BASE_URL = os.getenv("GO_API_BASE_URL", "http://localhost:8080")
|
||||||
INTERNAL_API_KEY = os.getenv("INTERNAL_API_KEY", "doormile-internal-2024")
|
INTERNAL_API_KEY = os.getenv("INTERNAL_API_KEY", "")
|
||||||
|
|
||||||
# Route Optimization API (Valhalla-backed road routing). The ExpressDispatchAgent
|
# Route Optimization API (Valhalla-backed road routing). The ExpressDispatchAgent
|
||||||
# calls its Doormile endpoint (/api/v1/optimization/doormile/sequence) to order a
|
# calls its Doormile endpoint (/api/v1/optimization/doormile/sequence) to order a
|
||||||
|
|||||||
@@ -3,6 +3,7 @@
|
|||||||
Doormile Full System Test Suite v2
|
Doormile Full System Test Suite v2
|
||||||
Fixed: correct routes, 2-step login, pricing payload, health endpoint
|
Fixed: correct routes, 2-step login, pricing payload, health endpoint
|
||||||
"""
|
"""
|
||||||
|
import os
|
||||||
import asyncio
|
import asyncio
|
||||||
import aiohttp
|
import aiohttp
|
||||||
import json
|
import json
|
||||||
@@ -13,14 +14,17 @@ import redis.asyncio as aioredis
|
|||||||
from datetime import datetime
|
from datetime import datetime
|
||||||
|
|
||||||
# ── Config ────────────────────────────────────────────────────────────────────
|
# ── Config ────────────────────────────────────────────────────────────────────
|
||||||
API_BASE = "https://api.doormile.com"
|
from dotenv import load_dotenv
|
||||||
NATS_URL = "nats://66.116.226.161:4223"
|
load_dotenv()
|
||||||
NATS_USER = "doormile"
|
|
||||||
NATS_PASSWORD = "Package@321#"
|
API_BASE = os.getenv("GO_API_BASE_URL", "https://api.doormile.com")
|
||||||
REDIS_HOST = "66.116.226.255"
|
NATS_URL = os.environ["NATS_URL"]
|
||||||
REDIS_PORT = 6380
|
NATS_USER = os.getenv("NATS_USER", "")
|
||||||
REDIS_PASSWORD = "Package@321#"
|
NATS_PASSWORD = os.getenv("NATS_PASSWORD", "")
|
||||||
INTERNAL_KEY = "doormile-internal-2024"
|
REDIS_HOST = os.environ["REDIS_HOST"]
|
||||||
|
REDIS_PORT = int(os.getenv("REDIS_PORT", "6379"))
|
||||||
|
REDIS_PASSWORD = os.getenv("REDIS_PASSWORD", "")
|
||||||
|
INTERNAL_KEY = os.environ["INTERNAL_API_KEY"]
|
||||||
|
|
||||||
# Test customer — uses the one created by Window 1 test
|
# Test customer — uses the one created by Window 1 test
|
||||||
TEST_PHONE = "9900000001"
|
TEST_PHONE = "9900000001"
|
||||||
|
|||||||
9
main.py
9
main.py
@@ -204,11 +204,12 @@ Usage:
|
|||||||
python main.py --portal Launch Streamlit customer portal
|
python main.py --portal Launch Streamlit customer portal
|
||||||
python main.py --help Show this help
|
python main.py --help Show this help
|
||||||
|
|
||||||
Infrastructure (set in .env):
|
Infrastructure (set in .env — see .env.example):
|
||||||
NATS nats://doormile@66.116.226.161:4223
|
NATS NATS_URL / NATS_USER / NATS_PASSWORD
|
||||||
Redis 66.116.226.255:6380
|
Redis REDIS_HOST / REDIS_PORT / REDIS_PASSWORD
|
||||||
PG DB_HOST / DB_PORT / DB_NAME / DB_USER / DB_PASSWORD
|
PG DB_HOST / DB_PORT / DB_NAME / DB_USER / DB_PASSWORD
|
||||||
API GO_API_BASE_URL
|
API GO_API_BASE_URL / INTERNAL_API_KEY
|
||||||
|
LLM ANTHROPIC_API_KEY / LLM_MODEL
|
||||||
""")
|
""")
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
3
pytest.ini
Normal file
3
pytest.ini
Normal file
@@ -0,0 +1,3 @@
|
|||||||
|
[pytest]
|
||||||
|
testpaths = tests
|
||||||
|
asyncio_mode = auto
|
||||||
Reference in New Issue
Block a user